The package includes tests, a substantial README, and active build and security tooling. Its license metadata conflicts with the detected MIT file, and the project is only seven days old with all recent commits from one contributor.
68%
Total Score
50
86
75
The artifact contains an MIT license file, so the release is licensed, but the manifest declares it proprietary and does not match the detected license. That conflict reduces transparency for consumers.
The package is only 7 days old with 4 releases, all in the last 12 months, and releases are clustered roughly 25 minutes apart. This shows active initial development but provides little evidence of long-term maintenance.
One contributor made all 4 commits in the last 3 months, leaving no demonstrated contributor redundancy. This increases continuity risk if that maintainer becomes unavailable.
The repository has 4 commits in the last 3 months, so there is recent activity, but the volume is modest for a newly published package and does not yet demonstrate durable maintenance.
The repository has no security policy. This is a transparency and reporting gap, though it is not by itself evidence of abandonment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
liquidstack/blog Version * | — | — |
liquidstack/core Version ^1.31 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
phpmailer/phpmailer Version ^6.9 | — | — |
liquidstack/webadmin Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.